Security Evaluation 3
Out: Tuesday, May 24
Due: Tuesday, May 31 (start of class)
Description
At the end of class on April 3, we did an exercise in which everyone evaluated
the security of a real product. We also looked at other real systems in this course.
For this security evaluation, you are to do this exercise again,
this time for the new EEG gaming product from Emotiv: http://www.emotiv.com/2_0/2_1.htm.
Please provide the following:
- Summary of the product (given the information that you can easily find online).
This should be at a very high level,
around one or two paragraphs in length. State the parts that are relevant
to your observations below.
If you need to make assumptions about the product, please be sure to state what your assumptions are.
- State three assets and security goals. Please explain why the security goal is important. This should be around one or two sentences per asset/goal.
- State three potential adversaries and threats. You should have around
one or two sentences per adversary/threat.
- State three potential weaknesses. Again, justify your answer with around one or two sentences per weakness.
Hypothesize about how one might protect against these weaknesses.
We realize that there's not too much public information about the Emotiv product online.
That's OK. Just state your assumptions.
Extra credit may be awards for extreme creativity.
(And remember, some adversaries may be very creative!)